First published: Thu Oct 19 2017(Updated: )
Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent: Security). Supported versions that are affected are 9.3.5 and 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Agile PLM accessible data. CVSS 3.0 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Agile Product Lifecycle Management | =9.3.5 | |
Oracle Agile Product Lifecycle Management | =9.3.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-10299 is considered a critical vulnerability that can be easily exploited by low privileged attackers.
To fix CVE-2017-10299, upgrade Oracle Agile PLM to versions 9.3.7 or later as recommended by Oracle.
CVE-2017-10299 affects Oracle Agile PLM versions 9.3.5 and 9.3.6.
Yes, CVE-2017-10299 can be exploited remotely via HTTP by an attacker with low privileges.
The impact of CVE-2017-10299 allows unauthorized access and potential compromise of Oracle Agile PLM.